Junglewise Threat Intelligence

CVE-2026-40228: systemd systemd-journald ANSI escape sequence injection in wall messages

CVE-2026-40228 · Severity: low · CVSS 2.9 · Published 2026-04-10

Technologies: Systemd Project Systemd. Vendors: Systemd Project.

Executive brief

A vulnerability in systemd-journald allows a local user to send malicious control codes to the terminal screens of other users, including administrators. This occurs because the system fails to clean up special characters in emergency log messages before broadcasting them to all active users. An attacker could use this to trick an administrator's terminal into executing unauthorized commands or stealing sensitive data if the administrator is using a vulnerable terminal application.

Technical details

systemd-journald in systemd 259 is vulnerable to an injection flaw when 'ForwardToWall=yes' is enabled (often the default). The component fails to sanitize ANSI escape sequences from log messages before broadcasting them via the 'wall' mechanism. A local, unprivileged attacker can use the 'logger -p emerg' command to send crafted messages containing terminal escape sequences. If an administrator or another user is using a terminal emulator vulnerable to escape sequence injection (such as certain versions of XTerm), the attacker can achieve arbitrary code execution or unauthorized file access in the context of that user. Mitigation involves setting 'ForwardToWall=no' in journald.conf.

Affected products

  • systemd project systemd 259

Timeline

  • 2025-12-23: disclosed: Privately reported to upstream developers
  • 2026-04-07: advisory: Public disclosure by researcher
  • 2026-04-10: other: CVE assigned

References

Related threats